User Manual Managed Switches
174
RADIUS server. The switch only supports
the MD5-Challenge authentication method, so the
RADIUS server must be configured accordingly.
When authentication is complete, the RADIUS server
sends a success or failure indication, which in turn
causes the switch to open up or block traffic for that
particular client. The advantage of MAC-based
authentication over 802.1X-based authentication is
that the clients don't need special supplicant software
to authenticate. The disadvantage is that MAC
addresses can be spoofed by malicious users -
equipment whose MAC address is a valid RADIUS
user can be used by anyone. Also, only the
MD5-Challenge method is supported. The maximum
number of clients that can be attached to a port can be
limited using the Port Security Limit Control
functionality.
RADIUS-Assigned QoS Enabled
Setting
Description
Factory
Default
Check / Uncheck
When RADIUS-Assigned QoS is both globally
enabled and enabled (checked) on a given port, the
switch reacts to QoS Class information carried in the
RADIUS Access-Accept packet transmitted by the
RADIUS server when a supplicant is successfully
authenticated. If present and valid, traffic received on
the supplicant's port will be classified to the given QoS
Class. This option is only available for single-client
modes (Port-based 802.1X and Single 802.1X).
Unchecked
RADIUS-Assigned VLAN Enabled
Setting
Description
Factory
Default
Check / Uncheck
When RADIUS-Assigned VLAN is both globally
enabled and enabled (checked) for a given port, the
switch reacts to VLAN ID information carried in the
RADIUS Access-Accept packet transmitted by the
RADIUS server when a supplicant is successfully
authenticated. If present and valid, the port's Port
VLAN ID will be changed to this VLAN ID, the port will
be set to be a member of that VLAN ID, and the port
will be forced into VLAN unaware mode. Once
assigned, all traffic arriving on the port will be
classified and switched on the RADIUS-assigned
VLAN ID. This option is only available for single-client
modes (Port-based 802.1X and Single 802.1X).
Unchecked